Security Magazine logo
  • Sign In
  • Create Account
  • Sign Out
  • My Account
  • NEWS
  • MANAGEMENT
  • PHYSICAL
  • CYBER
  • BLOG
  • COLUMNS
  • EXCLUSIVES
  • SECTORS
  • EVENTS
  • MEDIA
  • MORE
  • EMAG
  • SIGN UP!
cart
facebook twitter linkedin youtube
  • NEWS
  • Security Newswire
  • Technologies & Solutions
  • MANAGEMENT
  • Leadership Management
  • Enterprise Services
  • Security Education & Training
  • Logical Security
  • Security & Business Resilience
  • Profiles in Excellence
  • PHYSICAL
  • Access Management
  • Fire & Life Safety
  • Identity Management
  • Physical Security
  • Video Surveillance
  • Case Studies (Physical)
  • CYBER
  • Cybersecurity News
  • More
  • COLUMNS
  • Cyber Tactics
  • Leadership & Management
  • Security Talk
  • Career Intelligence
  • Leader to Leader
  • Cybersecurity Education & Training
  • EXCLUSIVES
  • Annual Guarding Report
  • Most Influential People in Security
  • The Security Benchmark Report
  • The Security Leadership Issue
  • Top Guard and Security Officer Companies
  • Top Cybersecurity Leaders
  • Women in Security
  • SECTORS
  • Arenas / Stadiums / Leagues / Entertainment
  • Banking/Finance/Insurance
  • Construction, Real Estate, Property Management
  • Education: K-12
  • Education: University
  • Government: Federal, State and Local
  • Hospitality & Casinos
  • Hospitals & Medical Centers
  • Infrastructure:Electric,Gas & Water
  • Ports: Sea, Land, & Air
  • Retail/Restaurants/Convenience
  • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
  • Industry Events
  • Webinars
  • Solutions by Sector
  • Security 500 Conference
  • MEDIA
  • Videos
  • Podcasts
  • Polls
  • Photo Galleries
  • Videos
  • Cybersecurity & Geopolitical Discussion
  • Ask Me Anything (AMA) Series
  • MORE
  • Call for Entries
  • Classifieds & Job Listings
  • Continuing Education
  • Newsletter
  • Sponsor Insights
  • Store
  • White Papers
  • EMAG
  • eMagazine
  • This Month's Content
  • Advertise
Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementSecurity NewswireSecurity Enterprise ServicesSecurity Leadership and ManagementLogical SecuritySecurity & Business ResilienceSecurity Education & TrainingCybersecurity News

Clear and present danger: SaaS supply chain attacks

By Yoni Shohet
supply-chain-1170x658freepik.jpg
June 14, 2022

The democratization of IT has empowered users to choose best of breed Software as a Service (SaaS) applications that can drive efficiency and support business agility. While beneficial for business purposes, today’s rapidly scaling SaaS adoption renders security teams helpless in the face of overseeing this sprawl or governing it. As the number of applications used by organizations rises, so does SaaS-to-SaaS interconnectivity and the number of third-party integrations accelerated through the use of API tokens, OAuth third-party apps, SaaS marketplaces, and no/low code automated workflows. These integrations significantly expand supply chain access, as well as its corresponding risk and attack surfaces.


Security teams currently struggle with bridging the gap between alerts and mitigation of breaches, have limited visibility due to blind spots and lack of context, and focus only on monitoring human identities, leaving the growing number of non-human identities used for programmatic access and automated processes exposed to supply chain attacks. In just the past few months, we’ve witnessed three extraordinary attacks leveraging this growing risk vector.


As the dust of the Okta, MailChimp and GitHub breaches settles, organizations are experiencing a quick and brutal awakening to the fact that third-party interconnectivity is now a liability. Security teams and business leaders must attempt to resolve this dissonance in order to allow businesses to innovate and thrive while ensuring the keys to the kingdom are kept secure. There are crucial and practical steps that should be taken in order to proactively reduce risks associated with supply chains. This article briefly analyzes the three most recent attacks, illustrating the inherent risks of leaving your supply chain in the dark, and what should have been done to mitigate them.


March: The Okta Compromise

Following an extensive investigation, Okta executives disclosed that the infamous and malicious LAPSU$S group compromised the workstation of a Sitel engineer, a third-party vendor connected to Okta’s infrastructure. Potentially impacting hundreds of Okta customers, the attackers used the workstation which was logged into Okta’s customer support infrastructure to access Okta’s SuperUser application, used to configure Okta customer tenants — although, according to Okta, they were unsuccessful in implementing any configuration changes during this attack.


Hitting an industry soft spot, the Okta compromise sent waves of panic throughout the industry. As a core identity and access management (IAM) platform used by countless organizations, its high privilege access to business-critical applications within organizations increased concerns. Many organizations were distraught by the possibility that their Okta tenant was breached and questioned whether there were any attempts to leverage Okta’s trusted access to gain malicious unauthorized access to their applications. Taking control of their own internal security mechanisms, organizations implemented password rotations, multifactor authentication (MFA) resets, admin application programming interface (API) access tokens revocation and thorough audits and log reviews.


These remediation and protection measures were woefully overdue. Organizations should ensure that they have proper and continuous visibility and analysis of their configurations and activity logs, in order to help them be well prepared for such breaches, which will inevitably continue to destabilize supply chains in enterprises.


March: The MailChimp Breach

The company detected unauthorized access by attackers, gained by successfully conducting social engineering activities that targeted MailChimp employee accounts. The access to internal customer support and account administration tools allowed the attackers to access hundreds of MailChimp customer accounts and export data from them. Interestingly, many sources reported that the attackers were also able to access and abuse customer API keys that allowed them to launch phishing campaigns targeting the cryptocurrency and finance industries.


This attack illustrated the attackers’ sophistication and growing understanding that instead of using traditional access methods, they can amplify their capabilities by leveraging non-human identities to effectively scale their operations and remain undetected. Non-human or app-to-app integrations operate and act in the background, connecting through service accounts and are constantly ‘logged in’ and capitalized upon by malicious actors. Maintaining zero trust controls and least privilege access provisions on this rapidly expanding web of integrations is critical to ensure that tokens are not abused.


April: The GitHub Attack Campaign

GitHub identified indications of unauthorized access using stolen OAuth tokens, which were issued to two of its third-party vendors, Heroku (a Salesforce company) and Travis CI. Authenticating to the GitHub API using these stolen tokens, the attackers executed a highly targeted attack culminating in the downloading of dozens of private data repositories belonging to GitHub customers, including npm. GitHub suggested that the contents of these repositories could be used to allow the attackers to pivot into a much broader supply chain attack and gain access to additional infrastructure. With an understandable time gap between discovery, customer notification and remediation, attackers may have been able to rapidly expand their reach and carry out a wide supply chain attack.


It is clear that while GitHub’s SaaS application was not the source of the compromise, the lack of a continuously updated inventory of all existing third-party vendors and their access provisions (API keys, OAuth tokens, or other SaaS-to-SaaS integrations) is a significant handicap for rapid response and mitigation of attacks on third-party vendors. An informed incident response strategy must be based on information gleaned from the breached vendors, in order to ascertain whether the organization itself was impacted and assess the blast radius.


Trust You Must Manage

If 2022’s attack history is any indication, supply chain attacks leveraging SaaS-to-SaaS integrations are the vector of choice for malicious actors, and alarm bells should be ringing in every office, including the chief information security officers (CISOs) and the C-suite. Inevitably, the ever-expanding supply chain and use of third-party vendors will grow as SaaS users base the majority of their workloads, automated processes and trust on these non-human actors that drive transparency and interconnectivity. Attackers are also well aware of the benefits inherent in accessing these high-privileged backdoor keys to the kingdom and will continue to exploit them under the (un)watchful eye of security professionals. While remediation activities are crucial, protective measures including heightened visibility, management, proactive risk reduction and mitigation efforts should be incorporated into organizational security protocols.

KEYWORDS: cyber security risk management software as a service supply chain third-party security

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Yoni Shohet is CEO and Co-founder at Valence Security

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Cybersecurity
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Columns
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Logical Security
    By: Charles Denyer
close

1 COMPLIMENTARY ARTICLE(S) LEFT

Loader

Already Registered? Sign in now.

Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

Middle East Escalation, Humanitarian Law and Disinformation – Episode 25

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

The Money Laundering Machine: Inside the global crime epidemic - Episode 24

Security’s Top 5 – 2024 Year in Review

Security’s Top 5 – 2024 Year in Review

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

  • Duty of Care
    Sponsored byAMAROK

    Integrating Technology and Physical Security to Advance Duty of Care

Popular Stories

Internal computer parts

Critical Software Vulnerabilities Rose 37% in 2024

Coding

AI Emerges as the Top Concern for Security Leaders

Half open laptop

“Luigi Was Right”: A Look at the Website Sharing Data on More Than 1,000 Executives

Person working on laptop

Governance in the Age of Citizen Developers and AI

Shopping mall

Victoria’s Secret Security Incident Shuts Down Website

2025 Security Benchmark banner

Events

June 24, 2025

Inside a Modern GSOC: How Anthropic Benchmarks Risk Detection Tools for Speed and Accuracy

For today's security teams, making informed decisions in the first moments of a crisis is critical.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • org-security-freepik1170x658.jpg

    Cybercrime: A clear and present danger

    See More
  • Computer screen displaying code

    Are AI data poisoning attacks the new software supply chain attack?

    See More
  • cyber data

    CISA and NIST release new interagency resource: Defending against software supply chain attacks

    See More

Events

View AllSubmit An Event
  • August 27, 2025

    Risk Mitigation as a Competitive Edge

    In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing

Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • The Security Leadership Issue
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!